6.9

CVSS4.0

CVE-2025-46338 - Audiobookshelf Vulnerable to Cross-Site-Scripting Reflected via POST Request in /api/upload

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.21.0, an improper input handling vulnerability in the `/api/upload` endpoint allows an attacker to perform a reflected cross-site scripting (XSS) attack by submitting malicious payloads in the `libraryId` field. The unโ€ฆ

๐Ÿ“… Published: April 29, 2025, 4:34 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 1:52 p.m.

3.3

CVSS3.1

CVE-2025-46330 - Snowflake Connector for C/C++ retries malformed requests

libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, incorrectly treat malformed requests that caused the HTTP response status code 400, as able to be retried. This could hang the application until SF_CON_MAX_RETRY requests were sent. This issue hasโ€ฆ

๐Ÿ“… Published: April 29, 2025, 4:34 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 1:52 p.m.

9.8

CVSS3.1

CVE-2025-24252 -

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may be able to corrupt process memory.

๐Ÿ“… Published: April 29, 2025, 2:05 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 8:10 p.m.

5.5

CVSS3.1

CVE-2025-31197 -

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may cause an unexpected app termination.

๐Ÿ“… Published: April 29, 2025, 2:05 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 8:11 p.m.

5.5

CVSS3.1

CVE-2025-24179 -

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, visionOS 2.3, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, macOS Sequoia 15.3, tvOS 18.3. An attacker on the local network may be able to cause a denial-of-service.

๐Ÿ“… Published: April 29, 2025, 2:05 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 8:09 p.m.

5.5

CVSS3.1

CVE-2025-24270 -

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may be able to leak sensitive user information.

๐Ÿ“… Published: April 29, 2025, 2:05 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 8:11 p.m.

6.2

CVSS3.1

CVE-2025-24271 -

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An unauthenticated user on the same network as a signed-in Mac could send it AirPlโ€ฆ

๐Ÿ“… Published: April 29, 2025, 2:05 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 8:11 p.m.

7.7

CVSS3.1

CVE-2025-24206 -

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may be able to bypass authentication policy.

๐Ÿ“… Published: April 29, 2025, 2:05 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 8:10 p.m.

5.1

CVSS3.1

CVE-2025-24251 -

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, watchOS 11.4, visionOS 2.4. An attacker on the local network may cause an unexpected app termination.

๐Ÿ“… Published: April 29, 2025, 2:05 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 8:10 p.m.

5.5

CVSS3.1

CVE-2025-31202 -

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4. An attacker on the local network may be able to cause a denial-of-service.

๐Ÿ“… Published: April 29, 2025, 2:05 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 4:15 p.m.
Total resulsts: 291780
Page 10 of 29,178
ยซ previous page ยป next page
Filters